Live data from Hacker News

Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

modzero.com

21–30 of 167 posts

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#21

Working as a developer inside large enterprise is increasingly intolerable by the day, made possible by tools such as crowdstrike falcon. By the time your workstation is saddled with endpoint security, DLP, zero trust networking, antivirus, etc. it barely functions. And you can get in trouble for doing anything. Installing tree from homebrew can get you flagged on some naughty list where you have to justify why you n…

I recently finished an internship in a large company.

I wanted to install netcat to troubleshoot networking issues between windows and docker containers I was running.

Right when it was downloaded from scoop, it got deleted and I got a scary automated email.

My manager called me immediately, in the end it was cleared quickly but I did learn to be very carefull about what I try to download.

At first I didn't understand why netcat was being detected by the AV but then I remembered it can be used to set up a reverse shell.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#23

Anybody know their problems with the terms at HackerOne? I admit I don't know HackerOne's term exactly and I'm not that good at reading legalese.

A bit speculative, but the word "NDA" appears four times in their post.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#25
post #18

Earlier quoted context omitted.

There is a LOT of snake oil in the industry, but endpoint protection IS useful. Not every person is a Hacker News reading tech enthusiast. People download and do dumb shit. That is not to say every device needs it and at a max “check every process/file activity” level, though.

10% of Falcon is blocking dumb shit people do. 90% is blocking things people are supposed to be doing, and have been doing successfully so far. Nothing starts your week better than "After the latest definitions update, Falcon heuristic started quarantining your core business tools as suspicious".

Nobody else is running your binaries, so they don’t match the hashes of any of the trusted binaries in the database. Obviously they’re suspect & should be quarantined immediately!

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#26
post #18

Earlier quoted context omitted.

There is a LOT of snake oil in the industry, but endpoint protection IS useful. Not every person is a Hacker News reading tech enthusiast. People download and do dumb shit. That is not to say every device needs it and at a max “check every process/file activity” level, though.

10% of Falcon is blocking dumb shit people do. 90% is blocking things people are supposed to be doing, and have been doing successfully so far. Nothing starts your week better than "After the latest definitions update, Falcon heuristic started quarantining your core business tools as suspicious".

They fixed it with an update this month, but CrowdStrike was hooking /every/ single call to NtCreateUserProcess on my work machine last month, and you /know/ how electron-based apps work. VSCode took so long to launch its sub processes it would pop up a crash reporter. "Hello World" compiled from C++ would take a minute to launch sometimes. WSL straight up could not be started because the TTY timed out waiting for it.

For some reason java.exe startup was A-OK though so I started using JEdit again.

Aggravatingly, it would occasionally disappear my builds and then flag me to IT. My dude, I am hired as a developer of native windows C++ applications why the hell is this trash on my would-be workstation-class machine?

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#27

Anybody know their problems with the terms at HackerOne? I admit I don't know HackerOne's term exactly and I'm not that good at reading legalese.

A bit speculative, but the word "NDA" appears four times in their post.

I believe HackerOne has some restrictions on disclosure as with an NDA approval is needed.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#28
The same Crowdstrike that was a key player in Russiagate? Colour me shocked that they do things dumbly. Anyone still using them after that fiasco and its impact on the US should be ashamed.

https://thegrayzone.com/2021/10/30/crowdstrike-one-of-russia...

https://thegrayzone.com/2020/05/11/bombshell-crowdstrike-adm...

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#29

Anybody know their problems with the terms at HackerOne? I admit I don't know HackerOne's term exactly and I'm not that good at reading legalese.

A bit speculative, but the word "NDA" appears four times in their post.

Yea I noticed that, but what do they specifically not like about the NDA? afaik, HackerOne still makes vulnerability disclosure possible (and automatic if taking too long?)

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#30
post #18

Earlier quoted context omitted.

10% of Falcon is blocking dumb shit people do. 90% is blocking things people are supposed to be doing, and have been doing successfully so far. Nothing starts your week better than "After the latest definitions update, Falcon heuristic started quarantining your core business tools as suspicious".

They fixed it with an update this month, but CrowdStrike was hooking /every/ single call to NtCreateUserProcess on my work machine last month, and you /know/ how electron-based apps work. VSCode took so long to launch its sub processes it would pop up a crash reporter. "Hello World" compiled from C++ would take a minute to launch sometimes. WSL straight up could not be started because the TTY timed out waiting for it…

Because your organization's customers demanded your employer get some security certificate, and part of that certification is hoisting that BS on all users
Post reply on HN